Head of Governance and Compliance

Discovery – Information Governance and Security
Head of Governance and Compliance
About Discovery
Discovery’s core purpose is to make people healthier and to enhance and protect their lives. We seek out and invest in exceptional individuals who understand and support our core purpose, and whose own values align with those of Discovery. Our fast-paced and dynamic environment enables smart, self-driven people to be their best. As global thought leaders, Discovery is passionate about innovating in order to not only achieve financial success, but to ignite positive and meaningful change within our society.
About Information Governance and Security (IGS)
The Information Governance and Security function within the Discovery Group aims to provide assurance that the organisation’s information assets are adequately protected against threats on a continual basis. This is achieved by finding the right balance of information security and business freedom.
Key Purpose
This role resides in the CISO Office and its primary purpose is to serve as a senior leader within the Discovery Information Governance and Security structure (IGS). This individual will support the Deputy CISO with strategic planning and execution of governance and compliance requirements as well as to lead and manage the Governance and Compliance team. The role requires that a positive and collaborative culture is established to execute the end to end governance and compliance function. The role ensures that Discovery’s information assets are governed effectively, regulatory compliance obligations are met, and that governance frameworks, standards and policies are implemented and maintained to the standard set out.
Areas of responsibility may include but not limited
- Lead and manage the Governance and Compliance team to fulfil the security and privacy core purpose. Own the function and outcomes of allocating work, guiding performance, and ensuring quality delivery through a positive, collaborative work environment.
- Ensure that GIS continues to meet regulatory and compliance requirements. Provide guidance, oversee reviews and ensure a strong governance posture across the Group.
- Further develop, maintain, and improve the Integrated Information Management System (IIMS) to ensure ongoing security and privacy certification and audit readiness.
- Ensure that governance and compliance related frameworks are drafted with review and vetting of Policies, Standards, Processes, Procedures and/or any other relevant documentation as per the governance lifecycle and regulatory requirements, while maintaining an understanding of the impact and challenges facing the business.
- Provide input to new projects, technologies, and business initiatives with consultation to management, enabling the stakeholders and being a trusted advisor to them.
- Prepare and share assessments and reports for Leadership and various Executive committees. Ensure issues, risks and/ or gaps are clearly understood, articulated, communicated and tracked.
- Partner with the Deputy CISO and CISO Office to align governance and compliance priorities with the broader security and business strategies.
Personal Attributes and Skills
- Sound knowledge and experience in governance, compliance and risk frameworks
- Strong negotiation skills
- Excellent knowledge of technology environments
- The ability to articulate security and privacy in non-technical business impact terms
- Excellent written and oral presentation skills, ability to lead discussions and present complex ideas to all levels within the organization
- Business Writing Skills, Presentation and Facilitation Skills
- Customer Service Orientation, Result Orientation, Negotiation skills
- Personal organisation and time management skills
- Proper Time Management
- Professional Communication (written, verbal/presenting and listening)
- Interpersonal skills - Ability to build relationships with people from all different backgrounds and at different job levels
Qualifications & Experience
- Related Diploma/ Degree in IT, Security, Privacy or Law
- Industry standard qualifications such as CRISC, CGEIT
- Regulatory Compliance accreditation
- ISACA; IRMSA; Compliance Institute of South Africa (CISA)
Experience:
- 10 years of experience in Information Technology, Security and/or Privacy.
- Experience in IT Governance, IT assurance, legal and compliance.
- In depth knowledge of legislation and impacting international regulations relating to IT and able to interpret and apply legislation and governance requirements.
- Experience in control frameworks for Information Security, Privacy, Compliance and IT Governance Standards: ISO27001/2, ISO 27701, ISO31000, COBIT, King IV, NIST and ITIL.
EMPLOYMENT EQUITY
The Company’s approved Employment Equity Plan and Targets will be considered as part of the recruitment process. As an Equal Opportunities employer, we actively encourage and welcome people with various disabilities to apply.